Understanding that interoperable security playbooks will become a fundamental component of defenders' arsenal to decrease attack detection and response times, it is time to consider their position in structured sharing efforts. This report documents the process of extending Structured Threat Information eXpression (STIX) version 2.1, using the available extension definition mechanism, to enable sharing security playbooks, including Collaborative Automated Course of Action Operations (CACAO) playbooks.
翻译:由于认识到互可操作的安全手册将成为维权者减少攻击探测和反应时间的武库的基本组成部分,现在是考虑其在有条不紊的共享努力中的立场的时候了,本报告记录了利用现有扩展定义机制扩大结构威胁信息压缩2.1版的过程,以便能够分享安全手册,包括合作自动行动程序手册。